Lessons from Biggest HIPAA Breaches of 2022
It has been another bad year for healthcare data breaches, with some of the biggest HIPAA breaches of 2022 resulting in the impermissible disclosure of well over a million records. While it does not currently look like last year’s record of 714 data breaches of 500+ records will be exceeded this year, with 674 data breaches reported up until December 22, 2022, any reduction is likely to be minimal. In addition to the high number of data breaches, 2022 stands out for the sheer number of healthcare records breached, which currently stands at 49.8 million records. That’s more than any other year to date apart from 2015 when Anthem Inc reported its 78.8 million-record data breach. In 2022, 12 data breaches were reported that exposed more than 1 million records, and a further 13 data breaches exposed between 500,000 and 1 million records. The Biggest HIPAA Breaches of 2022 One notable observation from the biggest HIPAA breaches of 2022 is the number that occurred at business associates of HIPAA-covered entities. Many of these business associate data breaches affected dozens of...
Medical Device Cybersecurity Provisions Included in Omnibus Appropriations Bill
The text of a $1.7 trillion omnibus appropriations bill has been released by the House and Senate Appropriations Committees which, if passed, will ensure that the government remains funded until September 30, 2023. The Senate has already started debating the bill and the House is due to consider the bill this week. The bill must be signed by the president on Friday this week, when government funding is set to expire. The 4,155-page bill includes many healthcare provisions that will help hospitals and health systems provide better care for patients. These include the prevention of the 4% Medicare PAYGO cuts to providers, financial support for rural hospitals to ensure they can continue to operate, measures to help states prepare for Medicaid eligibility changes when the COVID-19 Public Health Emergency comes to an end, and extensions and expansions of telehealth flexibilities until December 31, 2024. This will help to ensure that telehealth and hospital-at-home programs can continue to provide convenient and accessible medical treatment for patients. The bill will also provide...
November 2022 Healthcare Data Breach Report
November was a relatively quiet month for healthcare data breaches with 31% fewer breaches reported than the previous month. November’s total of 49 breaches of 500 or more records was also well below the 12-month average of 58 breaches a month. 643 healthcare data breaches have been reported to the HHS’ Office for Civil Rights so far in 2022, which makes this year the second worst year to date for healthcare data breaches. Despite the fall in reported breaches, the number of breached records increased by 10% from October. November was the worst month of 2022 in terms of the number of breached healthcare records, with 6,904,441 records exposed or impermissibly disclosed – Well above the 12-month average of 3.99 million records a month. So far in 2022, 44,852,648 healthcare records have been breached. Largest Healthcare Data Breaches in November 17 breaches of 10,000 or more records were reported to OCR in November, five of which involved more than half a million records and three incidents involved the impermissible disclosure of more than 1 million records. The largest...
Six Data Breaches Reported by Healthcare Providers and Business Associates
Work Health Solutions, a San Jose, CA-based occupational health services provider, has confirmed that the protected health information of 13,157 individuals has been exposed and potentially obtained by unauthorized individuals who had access to an employee email account between February 16, 2-022 and March 24, 2022. Following an investigation by third-party cybersecurity professionals, Work Health Solutions determined that the email account contained files that included the information of individuals who had received services from the company. The manual review of those files concluded on October 11, 2022. Work Health Solutions then verified contact information and sent notifications on November 9, 2022. The exposed files contained names, Social Security numbers, driver’s license numbers, health insurance information, and/or medical information. Complimentary credit monitoring services have been offered to individuals whose Social Security numbers were potentially compromised. Work Health Solutions said it continuously evaluates and modifies its practices to improve privacy and...
Critical Citrix ADC and Gateway Vulnerability Exploited in Attacks on Healthcare Organizations
Citrix Application Delivery Controller (ADC) and Citrix Gateway users have been urged to check to make sure that their systems are not vulnerable to a critical unauthenticated remote code execution vulnerability, which is being actively exploited by a highly capable Chinese advanced persistent threat (APT) actor and potentially other state-sponsored hacking groups. Citrix ADC is a comprehensive application delivery and load-balancing solution that is used by healthcare organizations to ensure the constant availability of critical clinical applications, including electronic medical records. Citrix Gateway is used by healthcare organizations for remote access and for providing single sign-on across all applications. The Citrix ADC and Gateway authentication bypass vulnerability is tracked as CVE-2022-27518 and has been assigned a CVSS v3 severity score of 9.8 out of 10. The flaw can be exploited remotely by an unauthenticated actor to execute code and completely compromise the system. Mandiant has observed a Chinese state-sponsored hacking group exploiting the flaw. The APT actor is...



